Skip to content

Biggest-ever hack attack used basic Internet flaw

February 11, 2014

ntp attack

Monday, February 10, hackers are reported to have exploited a fundamental weakness in the Internet itself to stage a massive Distributed Denial of Service (DDoS) attack against unidentified computer servers in Europe.

Rather than exploiting flaws in a computer operating system, Monday’s attack instead used known weaknesses in the Network Time Protocol (NTP), a nearly 30-year-old Internet system used to synchronize computer clocks around the world.

The attack was against a client of the online security firm Cloudflare,

Cloudflare’s CEO Matthew Prince tweeted word of the attack on one of his clients, describing it as “very big” — about 400 gigabits per second (Gbps) — the “biggest” of its kind. 100Gbps larger than an attack on anti-spam service Spamhaus last year. He also said his company was mitigating the effects of the attack.

Attack was only a matter of time

Online security experts, including Cloudflare, had predicted this kind of “NTP amplification/reflection” DDoS attack.

The NTP system still functions pretty much as it did when it began operating in 1985. There are thousands of Network Time Protocol (NTP) servers designed to keep computers connected to the Internet synchronized to the correct time. The system was not designed with security in mind.

To synchronize its clock over the Internet a computer sends a request to a NTP server in the form of a small amount of data. The NTP server in turn replies with time data.

The attackers used two known weaknesses of the NTP system:

  • The NTP sends back more data than it receives, giving hackers more bang for their buck.
  • The NTP can be tricked into sending the data back to a different computer.

The attack likely used many, many, computers simultaneously sending time requests to the NTP. Hackers “spoofed” their location to divert the massive amounts of NTP data to flood a single target.

The object of such a Denial of Service attack is to overwhelm the target, say a Website’s server, with so much traffic that it crashes.

From → Internet

Leave a Comment

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: